Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-xc4w-28g8-vqm5: Path Traversal in Gravitee API Management

HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.

ghsa
#git

Path Traversal in Gravitee API Management

Moderate severity GitHub Reviewed Published Aug 24, 2022 • Updated Aug 30, 2022

Related news

CVE-2019-25075: GitHub - gravitee-io/gravitee-api-management: Gravitee.io - OpenSource API Management

HTML injection combined with path traversal in the Email service in Gravitee API Management before 1.25.3 allows anonymous users to read arbitrary files via a /management/users/register request.